operating model · version 2026.1
Federated Cloud Governance Model
A hub-and-spoke pattern that separates enterprise guardrails from business-domain ownership and platform execution.
Accessible diagram transcript
Objects
- Enterprise cloud governance: Guardrails and portfolio (Governance)
- Security authority: Control requirements (Authorities)
- Architecture authority: Reference patterns (Authorities)
- FinOps: Economics and allocation (Governance)
- Vendor management: Commercial governance (Governance)
- Domain platform A: Domain-owned outcomes (Engineering)
- Domain platform B: Domain-owned outcomes (Engineering)
- Domain platform C: Domain-owned outcomes (Engineering)
Directed relationships
- enterprise → security: delegates guardrails (authority)
- enterprise → architecture: delegates standards (authority)
- enterprise → finops: sets economics (handoff)
- enterprise → vendor: sets sourcing (handoff)
- security → domain-a: conditions (authority)
- architecture → domain-b: patterns (authority)
- finops → domain-c: unit economics (handoff)
- domain-a → enterprise: evidence (feedback)
- domain-b → enterprise: evidence (feedback)
- domain-c → enterprise: evidence (feedback)
When to use it
Use when several business units need autonomy without fragmenting policy, architecture and control evidence.
What to challenge
- Separate accountable authority from delivery execution.
- Make every important handoff directional and reviewable.
- Treat this reference pattern as a starting point, not a prescription.
Adapt it responsibly
- Rename functions to match the organization vocabulary.
- Remove elements that are genuinely out of scope.
- Validate decision rights and handoffs with accountable stakeholders.
Model contents
8 objects and 10 directed relationships. Every object keeps a stable semantic ID.
One model, multiple representations
The browser view and editable file are generated from the same canonical graph, so labels, roles and relationship direction stay aligned.
Clear visual grammar
Shape, color and connector style distinguish actors, governance, authorities, services, engineering, operations and providers.